CVE-2026-84434
- EPSS 0.7%
- Veröffentlicht 19.09.2026 02:27:09
- Zuletzt bearbeitet 21.09.2026 13:33:33
The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.1.0.4 via the upload_file function. This is due to a mismatch between the field validation pipeline and the file persistence pipelin...
CVE-2026-16649
- EPSS 0.19%
- Veröffentlicht 05.09.2026 06:37:56
- Zuletzt bearbeitet 08.09.2026 17:17:33
The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Post Body Field Value in all versions up to, and including, 2.10.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthen...
CVE-2026-19513
- EPSS 0.5%
- Veröffentlicht 01.09.2026 13:29:50
- Zuletzt bearbeitet 01.09.2026 20:47:54
The Gravity Forms plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 3.0.2. This is due to insufficient validation of multi-file upload chunk state in the `GFAsyncUpload::upload()` function, where public...
CVE-2026-12997
- EPSS 0.62%
- Veröffentlicht 15.07.2026 18:34:13
- Zuletzt bearbeitet 15.07.2026 19:50:25
The Gravity Forms plugin for WordPress is vulnerable to Directory Traversal in all versions up to, and including, 2.10.4 via the 'gform_uploaded_files' parameter parameter. This makes it possible for unauthenticated attackers to read the contents of ...
CVE-2026-5110
- EPSS 0.25%
- Veröffentlicht 02.05.2026 05:29:30
- Zuletzt bearbeitet 05.05.2026 19:16:18
The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping in the SingleProduct field when used inside a...
CVE-2026-5109
- EPSS 0.25%
- Veröffentlicht 02.05.2026 05:29:29
- Zuletzt bearbeitet 05.05.2026 19:16:18
The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient validation and output escaping of Product Option field values. The vulnerability exists because th...
CVE-2026-5111
- EPSS 0.25%
- Veröffentlicht 02.05.2026 05:29:29
- Zuletzt bearbeitet 05.05.2026 19:16:18
The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping on Hidden Product field values when used inside Repeater fiel...
CVE-2026-5112
- EPSS 0.23%
- Veröffentlicht 02.05.2026 05:29:28
- Zuletzt bearbeitet 05.05.2026 19:16:18
The Gravity Forms plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting in versions up to and including 2.10.0. This is due to insufficient input validation and output escaping of Calculation Product field product names wh...
CVE-2026-5113
- EPSS 0.24%
- Veröffentlicht 02.05.2026 05:29:28
- Zuletzt bearbeitet 05.05.2026 19:16:18
The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via Consent field hidden inputs in versions up to and including 2.10.0. This is due to a flawed state validation mechanism that fails open when input is sanitized by ...
CVE-2026-4394
- EPSS 0.29%
- Veröffentlicht 07.04.2026 23:25:28
- Zuletzt bearbeitet 24.07.2026 23:10:00
The Gravity Forms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Credit Card field's 'Card Type' sub-field (`input_<id>.4`) in all versions up to, and including, 2.9.30. This is due to the `get_value_entry_detail()` method ...